Legal
Privacy Policy
Last updated: 22 September 2025
Your privacy matters to us. This policy explains what we collect, why, and your rights under the Protection of Personal Information Act (POPIA).
1. Introduction & Scope
Ndayeni Solutions Pty Ltd (“Ndayeni Solutions”, “we”, “us”) is a South African registered information technology services company based at 4099 Finger Fish Street, Kaalfontein, Midrand, 1635. We provide IT support, computer repairs, networking & Wi-Fi, CCTV & security, printer & office technology, web design, graphic design, digital automation and digital skills training to small businesses and homes across South Africa.
This Privacy Policy explains how we collect, use, disclose and protect your personal information when you interact with us through our website at ndayenisolutions.co.za, our contact form, WhatsApp, email or telephone, our digital training academy, and during the delivery of our services. It applies to website visitors, enquiry contacts, training applicants, students and clients.
We are committed to protecting your privacy and complying with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) (“POPIA”), the Promotion of Access to Information Act, 2000 (Act No. 2 of 2000) and other applicable South African data protection laws. This policy is reviewed regularly and updated as our services evolve.
2. Information We Collect
We only collect personal information that is necessary for the purposes set out in this policy. We group what we collect into the following categories:
Personal information you provide directly
Full name, email address, phone number, South African ID or passport number, residential or business address, and related details you give us when you submit a contact form, apply for training, request a quote, become a client or enrol in a course.
Business information
Company name, your position or role, business address and related details you provide when you contact us on behalf of an organisation.
Technical information collected automatically
IP address, browser type and version, operating system, device information, referring pages and basic usage data collected automatically when you visit our website or use our online services.
Communication records
Records of emails, WhatsApp messages, telephone calls and meeting notes you exchange with us. We keep these to deliver and improve our service, to verify your identity and to keep an accurate history of your enquiry or project.
Special categories of personal information
We do not collect special personal information (such as health, religion, race, political opinions or biometric data) except where it is strictly necessary for a specific service you have requested. For example, CCTV installation may incidentally capture images of your property. In every such case, we will explain why and obtain your explicit consent before collecting or processing this information.
3. How We Use Your Information
We process your personal information for the following specific, limited purposes:
- Providing the IT services, support and maintenance you have requested from us.
- Responding to your enquiries, requests for quotes and follow-up communications.
- Processing training academy applications, enrolment and student administration.
- Issuing certificates of completion and verifying qualifications when you or a third party you authorised requests verification.
- Sending service-related communications such as appointment reminders, status updates and security notices.
- Billing, invoicing and account administration.
- Improving our services, website and customer experience.
- Complying with our legal obligations and keeping records we are required to maintain under South African law.
We do not use your personal information for any purpose that is incompatible with the purposes for which it was originally collected. Where we wish to use it for a new purpose, we will tell you first and, where required, seek your consent.
4. Legal Basis for Processing
Under POPIA (Sections 19 to 21), we may only process your personal information if we have a lawful basis to do so. We rely on the following lawful bases:
- Consent: you have given us clear, informed consent to process your personal information for a specific purpose.
- Performance of a contract: processing is necessary to deliver a service or enter into an agreement with you, such as on-site support, CCTV installation or training delivery.
- Legal obligation: we are required to process the information to comply with a law, for example keeping tax records for the South African Revenue Service (SARS) or reporting under the Financial Intelligence Centre Act (FIC Act) where applicable.
- Legitimate interests: processing is necessary for our legitimate interests (or those of a third party), such as retaining CCTV footage for client security, provided those interests are not overridden by your rights.
- Vital interests: processing is necessary to protect your vital interests, for example using emergency contact information during an incident at a training venue or client site.
6. Data Retention
We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, including any legal, accounting or reporting requirements. After that, we securely delete it or anonymise it so that it can no longer identify you.
Specific retention periods
- Enquiries & quotes12 months after last contact
- Client service records5 years (SARS record-keeping)
- Training academy records7 years (SAQA requirements)
- CCTV footage30–90 days per client contract
- Website & server logs30 days
- Issued certificatesPermanent (verification purpose)
When retention is no longer required, personal information is securely deleted or rendered permanently anonymous using industry-standard methods. Backups containing deleted information are overwritten on the next scheduled backup rotation.
7. Security Measures
We take the security of your personal information seriously and apply a combination of technical, physical and organisational measures to protect it against unauthorised access, loss, destruction, alteration or disclosure.
Technical
- TLS encryption for data in transit.
- Encrypted databases at rest.
- Secure password hashing using PBKDF2 with unique salts.
- Strict access controls and least-privilege accounts.
- Regular security review and dependency updates.
Physical
- Secure storage of any physical client records.
- Locked premises and access-controlled workspaces.
- Secure disposal of printed personal information.
Organisational
- Staff training on POPIA and data handling.
- Written confidentiality agreements with all staff.
- Least-privilege access to systems and records.
- Documented incident response procedure.
Incident response: In the event of a confirmed data breach that poses a real risk to your rights, we will take reasonable steps to contain the breach, notify affected data subjects and notify the Information Regulator as required by POPIA (Section 22), as soon as reasonably possible after the breach has been confirmed.
8. Your Rights Under POPIA
POPIA gives you specific rights over your personal information. The cards below summarise each right; you can exercise any of them at any time.
How to exercise your rights
Email us at info@ndayenisolutions.co.za with the subject line “POPIA Request” and tell us which right you wish to exercise. We will verify your identity and respond within 30 days as required by POPIA (Sections 23 to 24). There is no charge for reasonable requests, although a reasonable fee may apply to manifestly unfounded or excessive requests.
10. Children’s Privacy
Our services are not directed at children under the age of 18, and we do not knowingly collect personal information from children. Training academy applicants must be 18 or older, or have written consent from a parent or legal guardian.
If you are a parent or guardian and you believe we have collected personal information from your child without consent, please contact us using the details in Section 13 and we will take reasonable steps to delete that information.
11. International Transfers
Some of our service providers process personal information outside South Africa. Under POPIA (Sections 73 to 76), we will only transfer your personal information to a foreign country if that country has an adequate level of data protection, or if the transfer is protected by appropriate safeguards such as standard contractual clauses or binding corporate rules, or one of the other lawful grounds applies.
Specific providers and their regions:
- Vercel — global edge network. Serves the website from the location closest to you, under GDPR-aligned data processing terms.
- Supabase — chosen regional data centre. Stores application and academy data with encryption at rest and in transit.
- Google — United States with EU data-protection controls (Google Analytics and Google Business Profile, only used with your consent).
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, POPIA guidance or best practice. When we do, we will publish the updated version on this page with a new “Last updated” date at the top.
For material changes (such as new categories of information we collect or new third parties we share it with), we will also post a notice on our homepage for at least 30 days so you have an opportunity to review the changes before they take effect.
13. Contacting Us
If you have any questions about this Privacy Policy or wish to exercise any of your rights, please contact our Information Officer:
Nhlakanipho Ntshangase — Information Officer
Ndayeni Solutions Pty Ltd
4099 Finger Fish Street, Kaalfontein,
Midrand, 1635, South Africa
14. Complaints
We aim to resolve any privacy concern quickly and fairly. Please contact us first using the details in Section 13 — we will investigate and respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator (South Africa):
Information Regulator (South Africa)
5th Floor, River Side Office Park, 130 Nana Sita Street, Sunnyside, Pretoria
Please attempt to resolve your concern with us first. This gives us the opportunity to investigate, explain or put things right before the matter is escalated.
Need to ask something?
If you have a question about how we handle your personal information, we’re happy to help.
Contact usThis policy is provided for general information. For specific legal advice on POPIA compliance, consult a qualified attorney.